{"success":true,"data":{"threats":[{"id":"0c846a65-398e-4698-bd51-6e7fe2764865","slug":"cve-2026-107226","externalId":"GHSA-p2jm-6hj6-9rjg","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"AsyncHttpClient: Cookies received over plaintext HTTP can plant, overwrite or delete Secure cookies set over HTTPS","description":"### Impact\nThe cookie store ignores the scheme a `Set-Cookie` arrived on. draft-ietf-httpbis-rfc6265bis-22 (approved to obsolete RFC 6265, in the RFC Editor queue) Section 5.7 requires a user agent to ignore a cookie with the `Secure` attribute unless it arrived over a secure connection (step 13), and to ignore a non-Secure cookie from an insecure connection when it would overlay a Secure cookie the store already holds (step 16). Neither rule is implemented. The only `Secure` handling is on retrieval, where a Secure cookie is not sent over plaintext.\n\nSo anyone who can answer a plaintext request to a site can set, replace or delete the site's `Secure` cookies, and the next HTTPS request carries the attacker's value back inside TLS:\n\n```\nhttp://example.com   ->  Set-Cookie: SID=attacker-value; Secure; Path=/\nhttps://example.com  ->  Cookie: SID=attacker-value\n```\n\nThis does not need an attacker on the network path. A plaintext host under the same site reaches the HTTPS one by setting a domain cookie:\n\n```\nhttp://insecure.example.com  ->  Set-Cookie: SID=attacker-value; Secure; Domain=example.com; Path=/\nhttps://bank.example.com     ->  Cookie: SID=attacker-value\n```\n\nA plaintext `Set-Cookie` of the same name, domain and path overwrites a Secure cookie, and one with `Max-Age=0` deletes it. Depending on what the application does with the cookie, this is session fixation into the HTTPS session, an overwritten CSRF token, or the removal of a cookie the site relies on. Unlike GHSA-qjr7-w8pj-pmv9, which can only add a cookie, this replaces or deletes one, hence Integrity: High; the harm lands on the HTTPS site, hence Scope: Changed.\n\n### Affected versions\n* 3.x: up to and including 3.0.13\n* 2.x: from 2.1.0, when the cookie store was introduced, up to and including 2.16.1\n\n### Patches\nFixed in 3.0.14 on the 3.x line. A cookie with the `Secure` attribute is ignored unless the request was secure, and a non-Secure cookie from a request that did not use TLS is ignored when it would overlay a Secure cookie of the same name whose path its own path falls under. A plaintext response can therefore no longer plant, overwrite or delete a `Secure` cookie.\n\nWhen several cookies of one name match a request, the client sends only the first, so the order in which the store returns them decides which one is used. That order is now: on a secure request, cookies received in a secure context (HTTPS, WSS or plaintext loopback) first; then the request host's own cookies before cookies set for a parent domain; then, within one host, longer paths first. A plaintext attacker cannot outrank a cookie the site set over HTTPS by ordering or padding its own cookies, or by setting one before the site sets its own.\n\nPlaintext requests to `localhost`, or to an address literal that is a loopback address, count as secure, so a development server that sets `Secure` cookies over `http://localhost` gets them back. This is limited to the cookies such a server set itself: a `Secure` cookie that arrived over HTTPS is never sent over plaintext, loopback included, and a plaintext loopback port cannot overlay it. Numeric spellings that are not address literals, such as `127.0.0.256`, and names under `localhost` are not treated as loopback, because the client resolves them as names.\n\nThe 2.x line is end of life and will not receive a fix. Upgrade to 3.0.14.\n\n### Workarounds\nDo not share one `CookieStore` between plaintext and HTTPS origins that are not mutually trusted, including hosts under the same site. Disabling the cookie store also avoids it.\n\n### Details\n`ThreadSafeCookieStore.add(Uri, Cookie)` reduces the request to its host and path before storing, so the scheme never reaches the code that decides whether to keep a cookie. `get(Uri)` does read it, but only to leave `Secure` cookies out of plaintext requests.\n\nA narrower form survives the two storage rules on their own. The step 16 path test is one-way by design, so a plaintext `SID` for `Path=/` is legitimately stored beside a Secure `SID` for `Path=/account`, and both match a request under `/account`. The store returned matching cookies in hash order, and the client keeps only the first cookie of each name when it builds the request (`RequestBuilderBase.addCookieIfUnset`), so an attacker could decide which one was sent, for example by padding one plaintext response with filler cookies. The ordering described above closes it.\n\nThe fix does not stop an HTTPS host under the same site from setting a domain cookie for a name the request host never sets itself. Only a `__Host-` cookie name prefix prevents that, and the client does not enforce cookie name prefixes.\n\n### Attribution\n\nAI-assisted tools were used to support discovery and analysis.","cveId":"CVE-2026-107226","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","severity":"medium","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.14","pkg:maven/org.asynchttpclient/async-http-client >= 2.1.0, <= 2.16.1"],"cwes":["CWE-384","CWE-693"],"tags":["osv","osv:ghsa-p2jm-6hj6-9rjg","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-p2jm-6hj6-9rjg","type":"advisory","title":"OSV GHSA-p2jm-6hj6-9rjg"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-p2jm-6hj6-9rjg","type":"other","title":"OSV web"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/6ec7ee45034d154f502852a962d2891746fb82c1","type":"other","title":"OSV web"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:49:59.000Z","addedAt":"2026-10-08T18:42:42.551Z","updatedAt":"2026-10-08T18:42:42.551Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107226","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107226","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-p2jm-6hj6-9rjg"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-p2jm-6hj6-9rjg"}]},{"id":"28a7d82c-d466-46eb-880d-348bcd39b05c","slug":"cve-2026-107285","externalId":"CVE-2026-107285","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107285 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.","cveId":"CVE-2026-107285","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.12","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1"],"cwes":["CWE-319","CWE-522"],"tags":["nvd","status:received","osv","osv:ghsa-3wp9-xfwm-rjjf","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/6e9cb75a9b7259353f983fc90ca28b1da3742e18","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-3wp9-xfwm-rjjf","type":"advisory","title":"OSV GHSA-3wp9-xfwm-rjjf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107285","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00206,"epssPercentile":0.09691,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:04.637Z","addedAt":"2026-10-07T22:39:36.836Z","updatedAt":"2026-10-08T21:05:45.227Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107285","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107285","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-3WP9-XFWM-RJJF"}]},{"id":"d844cafd-7643-436d-a4a0-3537a2084384","slug":"cve-2026-107283","externalId":"CVE-2026-107283","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107283 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12  and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom rather than a cryptographically secure random source. Digest relies on an unpredictable cnonce to resist chosen-plaintext and credential precomputation attacks, so an observer able to infer generator state can reduce the protection of the authentication exchange. This issue is fixed in versions 3.0.12 and 2.16.1.","cveId":"CVE-2026-107283","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","severity":"low","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.12","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1"],"cwes":["CWE-338"],"tags":["nvd","status:received","osv","osv:ghsa-mfj3-87qq-382v","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/dca2d90db87f0144ea893a6858dca13c426d06b6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/e1f5fc88fe211d3f64032c33b91093ba3d5e793d","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-mfj3-87qq-382v","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-mfj3-87qq-382v","type":"advisory","title":"OSV GHSA-mfj3-87qq-382v"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107283","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00263,"epssPercentile":0.16592,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:04.327Z","addedAt":"2026-10-07T22:39:36.822Z","updatedAt":"2026-10-08T21:05:45.160Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107283","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107283","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-MFJ3-87QQ-382V"}]},{"id":"3257cfa9-4647-4984-8c96-0d2af6ddd2cc","slug":"cve-2026-107282","externalId":"CVE-2026-107282","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107282 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13  and 2.16.1, cross-host request replay updates the current request but leaves the target request and related proxy context pointing at the original origin. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination. Documented ResponseFilter failover and retry paths can trigger the replay. This issue is fixed in versions 3.0.13 and 2.16.1.","cveId":"CVE-2026-107282","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.13","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1"],"cwes":["CWE-319","CWE-441","CWE-522"],"tags":["nvd","status:received","osv","osv:ghsa-jmqq-x5g9-9p2w","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/15b254514a411623e5f1d8c99ea79c0f82f8a466","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/bbc31aed3b044f9f7a126cf689a8c8d7ad2ae1cb","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-jmqq-x5g9-9p2w","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-jmqq-x5g9-9p2w","type":"advisory","title":"OSV GHSA-jmqq-x5g9-9p2w"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107282","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00189,"epssPercentile":0.07775,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:04.167Z","addedAt":"2026-10-07T22:39:36.815Z","updatedAt":"2026-10-08T21:05:45.138Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107282","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107282","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-JMQQ-X5G9-9P2W"}]},{"id":"f7ce3b72-a2f0-4550-bfce-f20b365bd2a6","slug":"cve-2026-107280","externalId":"CVE-2026-107280","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107280 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13  and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain matching but does not reject public suffixes. A host beneath a suffix such as co.uk can set a cookie for that suffix, after which the shared cookie store sends it to unrelated hosts under the suffix. This can inject or overwrite session-relevant cookie values across origins. This issue is fixed in versions 3.0.13 and 2.16.1.","cveId":"CVE-2026-107280","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.13","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1"],"cwes":["CWE-1275"],"tags":["nvd","status:received","osv","osv:ghsa-f9m8-cv68-674w","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/330267895fe0bdb41bbd027ea6b151d38ee7c23d","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/d1f0ccec417092098d40242fee7dfac84bb3c21f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-f9m8-cv68-674w","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-f9m8-cv68-674w","type":"advisory","title":"OSV GHSA-f9m8-cv68-674w"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107280","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.0026,"epssPercentile":0.16297,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.810Z","addedAt":"2026-10-07T22:39:36.800Z","updatedAt":"2026-10-08T21:05:45.079Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107280","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107280","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-F9M8-CV68-674W"}]},{"id":"fb027b1d-b52d-48a8-b768-368532a235a4","slug":"cve-2026-107231","externalId":"CVE-2026-107231","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107231 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce as a Basic challenge. A malicious origin or proxy can label a challenge Digest while omitting or emptying the nonce, causing the client to resend the username and password using reversible Basic authentication. Both origin and proxy challenge parsers are affected. This issue is fixed in versions 3.0.13 and 2.16.1.","cveId":"CVE-2026-107231","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0.Beta1, < 3.0.13","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1"],"cwes":["CWE-319","CWE-522","CWE-757"],"tags":["nvd","status:received","osv","osv:ghsa-rqf5-2wxv-rjf4","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/8376866aa9b5a7653ad19db9d472692f875caa83","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/c8d639bf6ac341d377d610a93570bcd15565f1a6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rqf5-2wxv-rjf4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-rqf5-2wxv-rjf4","type":"advisory","title":"OSV GHSA-rqf5-2wxv-rjf4"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107231","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00237,"epssPercentile":0.13486,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.320Z","addedAt":"2026-10-07T22:39:36.777Z","updatedAt":"2026-10-08T21:05:45.000Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107231","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107231","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RQF5-2WXV-RJF4"}]},{"id":"211b9c97-7fb8-4ffb-993b-ffd36a7cc765","slug":"cve-2026-107230","externalId":"CVE-2026-107230","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107230 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT proxy logins can reuse a socket authenticated as a different identity. A later request is then executed under the first identity and can expose that identity's data or authority to another caller. In the affected execution path, SpnegoEngine, NTLM, Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.","cveId":"CVE-2026-107230","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.14","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, <= 2.16.1"],"cwes":["CWE-346","CWE-863"],"tags":["nvd","status:received","osv","osv:ghsa-v2j5-22fr-j62r","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-v2j5-22fr-j62r","type":"advisory","title":"OSV GHSA-v2j5-22fr-j62r"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107230","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00188,"epssPercentile":0.07716,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.133Z","addedAt":"2026-10-07T22:39:36.768Z","updatedAt":"2026-10-08T21:05:44.974Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107230","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107230","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-V2J5-22FR-J62R"}]},{"id":"7a469106-8ea7-492e-ba33-e593f4bb94b1","slug":"cve-2026-107228","externalId":"CVE-2026-107228","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107228 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 3.0.14, the enabled-by-default cookie store replaces a Cookie header explicitly supplied through setHeader or addHeader whenever the store contributes any cookie for the origin. In a shared client, stored cookies originating from one user can replace a different user's request cookie, causing the request to execute under the wrong session. This bypasses the earlier CVE-2024-53990 remediation, which covered cookies supplied through addCookie but not a directly supplied header. This issue is fixed in version 3.0.14.","cveId":"CVE-2026-107228","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"medium","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.14","pkg:maven/org.asynchttpclient/async-http-client >= 2.1.0, <= 2.16.1"],"cwes":["CWE-287"],"tags":["nvd","status:received","osv","osv:ghsa-2jwh-9rmr-j4xf","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-2jwh-9rmr-j4xf","type":"advisory","title":"OSV GHSA-2jwh-9rmr-j4xf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107228","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00301,"epssPercentile":0.20897,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:14.457Z","addedAt":"2026-10-07T22:39:36.533Z","updatedAt":"2026-10-08T21:05:43.958Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107228","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107228","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-2JWH-9RMR-J4XF"}]},{"id":"48280bc4-ead1-4632-9e67-1a1d53ec877a","slug":"cve-2026-107227","externalId":"CVE-2026-107227","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107227 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.","cveId":"CVE-2026-107227","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.14","pkg:maven/org.asynchttpclient/async-http-client >= 2.2.0, <= 2.16.1"],"cwes":["CWE-400","CWE-409"],"tags":["nvd","status:received","osv","osv:ghsa-x8v2-478q-2hvg","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x8v2-478q-2hvg","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-x8v2-478q-2hvg","type":"advisory","title":"OSV GHSA-x8v2-478q-2hvg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107227","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00432,"epssPercentile":0.35395,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:14.283Z","addedAt":"2026-10-07T22:39:36.526Z","updatedAt":"2026-10-08T21:05:43.928Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107227","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107227","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-X8V2-478Q-2HVG"}]},{"id":"cf527769-6ce2-48af-a134-5d3954fc1e78","slug":"cve-2026-106453","externalId":"CVE-2026-106453","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106453 — yawkat LZ4 Java provides LZ4 compression for Java.","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2.","cveId":"CVE-2026-106453","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"Maven","product":"at.yawk.lz4:lz4-java","affectedVersions":["pkg:maven/at.yawk.lz4/lz4-java < 1.11.2","pkg:maven/org.lz4/lz4-java <= 1.8.1"],"cwes":["CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-6cx8-rjf8-pr8g","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-6cx8-rjf8-pr8g","type":"advisory","title":"OSV GHSA-6cx8-rjf8-pr8g"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/yawkat/lz4-java","type":"vendor","title":"OSV package"}],"epssScore":0.00371,"epssPercentile":0.28981,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:27.457Z","addedAt":"2026-10-06T20:39:33.124Z","updatedAt":"2026-10-07T18:42:44.842Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106453","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6CX8-RJF8-PR8G"}]},{"id":"9907ceae-d4c4-4433-97d0-a73865fe8e93","slug":"cve-2026-106452","externalId":"CVE-2026-106452","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106452 — yawkat LZ4 Java provides LZ4 compression for Java.","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2.","cveId":"CVE-2026-106452","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"Maven","product":"at.yawk.lz4:lz4-java","affectedVersions":["pkg:maven/at.yawk.lz4/lz4-java < 1.11.2","pkg:maven/org.lz4/lz4-java <= 1.8.1"],"cwes":["CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-4v53-57pg-c464","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-4v53-57pg-c464","type":"advisory","title":"OSV GHSA-4v53-57pg-c464"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/yawkat/lz4-java","type":"vendor","title":"OSV package"}],"epssScore":0.00371,"epssPercentile":0.28981,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:27.317Z","addedAt":"2026-10-06T20:39:33.116Z","updatedAt":"2026-10-07T18:42:44.953Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106452","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-4V53-57PG-C464"}]},{"id":"fb5d2ace-6d7d-49cb-8433-e6fcf552e6c4","slug":"cve-2026-106451","externalId":"CVE-2026-106451","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106451 — yawkat LZ4 Java provides LZ4 compression for Java.","description":"yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4.","cveId":"CVE-2026-106451","cvssScore":7.3,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"Maven","product":"at.yawk.lz4:lz4-java","affectedVersions":["pkg:maven/at.yawk.lz4/lz4-java < 1.11.4","pkg:maven/org.lz4/lz4-java >= 1.7.0, <= 1.8.1"],"cwes":["CWE-367","CWE-377"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-mcr4-qmvw-px4g","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-mcr4-qmvw-px4g","type":"advisory","title":"OSV GHSA-mcr4-qmvw-px4g"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106451","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/yawkat/lz4-java","type":"vendor","title":"OSV package"}],"epssScore":0.00083,"epssPercentile":0.00225,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:27.173Z","addedAt":"2026-10-06T20:39:33.109Z","updatedAt":"2026-10-08T00:42:49.585Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106451","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106451","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-MCR4-QMVW-PX4G"}]},{"id":"4cdde95c-5165-4ef9-b7a7-f8713f456609","slug":"cve-2026-106450","externalId":"CVE-2026-106450","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106450 — yawkat LZ4 Java provides LZ4 compression for Java.","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4.","cveId":"CVE-2026-106450","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"Maven","product":"at.yawk.lz4:lz4-java","affectedVersions":["pkg:maven/at.yawk.lz4/lz4-java < 1.11.4","pkg:maven/org.lz4/lz4-java <= 1.8.1"],"cwes":["CWE-770"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-gm45-99xc-r7wv","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-gm45-99xc-r7wv","type":"advisory","title":"OSV GHSA-gm45-99xc-r7wv"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/yawkat/lz4-java","type":"vendor","title":"OSV package"}],"epssScore":0.00371,"epssPercentile":0.28981,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:27.037Z","addedAt":"2026-10-06T20:39:33.090Z","updatedAt":"2026-10-08T00:42:49.607Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106450","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-GM45-99XC-R7WV"}]},{"id":"046b46ae-a75d-4bb1-b821-3e32f2e4cb10","slug":"cve-2026-106449","externalId":"CVE-2026-106449","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106449 — yawkat LZ4 Java provides LZ4 compression for Java.","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.","cveId":"CVE-2026-106449","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"low","vendor":"Maven","product":"at.yawk.lz4:lz4-java","affectedVersions":["pkg:maven/at.yawk.lz4/lz4-java < 1.11.4","pkg:maven/org.lz4/lz4-java <= 1.8.1"],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-343h-94h5-c4wr","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-343h-94h5-c4wr","type":"advisory","title":"OSV GHSA-343h-94h5-c4wr"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/yawkat/lz4-java","type":"vendor","title":"OSV package"}],"epssScore":0.00339,"epssPercentile":0.25225,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:26.887Z","addedAt":"2026-10-06T20:39:33.082Z","updatedAt":"2026-10-08T00:42:49.798Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106449","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-343H-94H5-C4WR"}]},{"id":"5476745a-e3d2-406c-a427-5810fdaf6795","slug":"cve-2026-106123","externalId":"CVE-2026-106123","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106123 — The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.","description":"The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.35.0, ConnectionFactoryConfigurator.load() includes the raw uri value in wrapped exceptions when AMQP URI parsing fails. Because the URI may contain a plaintext username and password, startup logs, application performance monitoring systems, CI logs, and copied stack traces can disclose broker credentials to users who should not have access to them. This issue is fixed in version 5.35.0.","cveId":"CVE-2026-106123","cvssScore":5.7,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"Maven","product":"com.rabbitmq:amqp-client","affectedVersions":["pkg:maven/com.rabbitmq/amqp-client < 5.35.0"],"cwes":["CWE-509"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-h6w7-qmcm-q6xr","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/daca1875cdb8b8c0acce78f71103b21a05478446","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2052","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.35.0","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-h6w7-qmcm-q6xr","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-h6w7-qmcm-q6xr","type":"advisory","title":"OSV GHSA-h6w7-qmcm-q6xr"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106123","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client","type":"vendor","title":"OSV package"}],"epssScore":0.00143,"epssPercentile":0.03101,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:43.647Z","addedAt":"2026-10-06T20:39:30.439Z","updatedAt":"2026-10-07T18:42:44.477Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106123","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106123","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-H6W7-QMCM-Q6XR"}]},{"id":"42e87940-a70e-4835-90a8-810a6d950eba","slug":"cve-2026-106122","externalId":"CVE-2026-106122","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106122 — The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.","description":"The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An attacker who can submit an RPC message with a malformed echoed property can cause reply publication in RpcServer.mainloop() or tutorial-style consumers to throw an unchecked exception before acknowledgement. The broker requeues the message, allowing the same message to disable replacement consumers until the queue is purged. This issue is fixed in version 5.36.0.","cveId":"CVE-2026-106122","cvssScore":6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"Maven","product":"com.rabbitmq:amqp-client","affectedVersions":["pkg:maven/com.rabbitmq/amqp-client < 5.36.0"],"cwes":["CWE-172","CWE-248"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-7822-rcf6-97fx","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/b8bd750fa8c90690e859b18d6343b34421309020","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2065","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.36.0","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-7822-rcf6-97fx","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-7822-rcf6-97fx","type":"advisory","title":"OSV GHSA-7822-rcf6-97fx"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106122","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client","type":"vendor","title":"OSV package"}],"epssScore":0.00409,"epssPercentile":0.33072,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:43.467Z","addedAt":"2026-10-06T20:39:30.430Z","updatedAt":"2026-10-08T00:42:50.051Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106122","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106122","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-7822-RCF6-97FX"}]},{"id":"868530bb-89db-4d17-a46b-e1ed59b96096","slug":"cve-2026-106121","externalId":"CVE-2026-106121","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106121 — The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.","description":"The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at CharacterIterator.DONE. The default DefaultJsonRpcMapper passes JSON-RPC message bodies to this parser for JsonRpcServer and client replies. A truncated string causes the parser to append replacement end markers until heap exhaustion, while a line comment without a terminating newline can keep a thread consuming CPU indefinitely, resulting in denial of service. This issue is fixed in version 5.37.0.","cveId":"CVE-2026-106121","cvssScore":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"Maven","product":"com.rabbitmq:amqp-client","affectedVersions":["pkg:maven/com.rabbitmq/amqp-client < 5.36.1"],"cwes":["CWE-835"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-cqgh-8p3p-mx4m","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/25fad817291feff3195c32620117d295598f8b41","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2100","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.37.0","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-cqgh-8p3p-mx4m","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-cqgh-8p3p-mx4m","type":"advisory","title":"OSV GHSA-cqgh-8p3p-mx4m"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106121","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client","type":"vendor","title":"OSV package"}],"epssScore":0.00493,"epssPercentile":0.40388,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:43.193Z","addedAt":"2026-10-06T20:39:30.422Z","updatedAt":"2026-10-08T00:42:49.383Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106121","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106121","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-CQGH-8P3P-MX4M"}]},{"id":"4d706328-f95f-4845-81d6-32f4c9277337","slug":"cve-2026-61586","externalId":"GHSA-xm28-xvqc-gxxg","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution","description":"Copernik XML Factory through `0.1.1`, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables XInclude on a factory returned by `XmlFactories.newDocumentBuilderFactory()` or `XmlFactories.newSAXParserFactory()`, or on an `XMLReader` passed through `XmlFactories.harden()`. The library's documented guarantee that XInclude resolution stays disabled therefore does not hold on that provider.\n\nAn application that parses untrusted XML in this configuration can be made to resolve `xi:include` references, allowing an attacker to read local files (information disclosure) or, through `http` hrefs, reach internal network endpoints (SSRF).\n\nAll of the following conditions must hold for an application to be affected:\n- it obtains a factory from `XmlFactories.newDocumentBuilderFactory()` or `XmlFactories.newSAXParserFactory()`, or hardens an externally obtained `XMLReader` with `XmlFactories.harden()`;\n- the stock JDK provider is in effect, that is, Apache Xerces is not on the classpath;\n- XInclude is enabled, by calling `setXIncludeAware(true)` or the equivalent reader feature;\n- it parses XML from an untrusted source.\n\nThe Xerces provider (selected when Xerces is on the classpath) and the Android provider are not affected.\n\nApplications are advised to upgrade to `0.1.2`, which fixes the defect. As a workaround add Apache Xerces (`xercesImpl`) to the classpath so the library selects its unaffected Xerces provider.\n\n### Acknowledgements\n\nThe maintainer thank the following people for finding, reporting, and helping to remediate this issue:\n\n- Finders: Ta Duc Thien and Duc Anh Nguyen (Danzation)\n- Remediation developer: Ta Duc Thien\n- Tooling: Claude Code (Anthropic), Claude Opus 4.8","cveId":"CVE-2026-61586","cvssScore":null,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","severity":"high","vendor":"Maven","product":"eu.copernik:copernik-xml-factory","affectedVersions":["pkg:maven/eu.copernik/copernik-xml-factory < 0.1.2"],"cwes":["CWE-611"],"tags":["osv","osv:ghsa-xm28-xvqc-gxxg","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-xm28-xvqc-gxxg","type":"advisory","title":"OSV GHSA-xm28-xvqc-gxxg"},{"url":"https://github.com/copernik-eu/copernik-xml-factory/security/advisories/GHSA-xm28-xvqc-gxxg","type":"other","title":"OSV web"},{"url":"https://github.com/copernik-eu/copernik-xml-factory/commit/2fa042c44931b0a4ddd585d62b97a8a987efd6c6","type":"other","title":"OSV web"},{"url":"https://github.com/copernik-eu/copernik-xml-factory/commit/e5febc6039ed4b0088245acb80ed7d6d6a7f5537","type":"other","title":"OSV web"},{"url":"https://github.com/copernik-eu/copernik-xml-factory","type":"vendor","title":"OSV package"},{"url":"https://github.com/copernik-eu/copernik-xml-factory/releases/tag/v0.1.2","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T18:27:17.000Z","addedAt":"2026-10-02T19:54:22.673Z","updatedAt":"2026-10-02T19:54:22.673Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61586","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61586","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-xm28-xvqc-gxxg"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-xm28-xvqc-gxxg"}]},{"id":"3e90517e-58d0-4971-b2ec-8cbdef2bdb73","slug":"cve-2026-54049","externalId":"CVE-2026-54049","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-54049 — Sakai is a Collaboration and Learning Environment (CLE).","description":"Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post. This issue has been patched in versions 23.5, 25.3, and 26.0.","cveId":"CVE-2026-54049","cvssScore":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","severity":"high","vendor":"Maven","product":"org.sakaiproject.conversations:sakai-conversations-impl","affectedVersions":["pkg:maven/org.sakaiproject.conversations/sakai-conversations-impl >= 23.0, <= 23.3","pkg:maven/org.sakaiproject.kernel/sakai-kernel-impl >= 23.0, <= 23.3","pkg:maven/org.sakaiproject.rubrics/rubrics-impl >= 23.0, <= 23.3"],"cwes":["CWE-79"],"tags":["osv","osv:ghsa-w2x5-gv52-9ccv","ecosystem:maven","nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-w2x5-gv52-9ccv","type":"advisory","title":"OSV GHSA-w2x5-gv52-9ccv"},{"url":"https://github.com/sakaiproject/sakai/security/advisories/GHSA-w2x5-gv52-9ccv","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/sakaiproject/sakai/commit/2696b4b48cbef2e81512f52f84f7477adff78b27","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sakaiproject/sakai","type":"vendor","title":"OSV package"},{"url":"https://github.com/sakaiproject/sakai/releases/tag/23.5","type":"other","title":"OSV web"}],"epssScore":0.00255,"epssPercentile":0.15735,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T20:17:25.587Z","addedAt":"2026-08-24T19:54:27.500Z","updatedAt":"2026-10-06T03:50:41.573Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54049","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-54049","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-W2X5-GV52-9CCV"}]},{"id":"92895c26-c082-4cc6-bb78-7586c3635f00","slug":"cve-2026-103922","externalId":"CVE-2026-103922","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103922 — Capacitor is a cross-platform native runtime for web applications.","description":"Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the response as a document at the application's own origin, allowing script in that response to access same-origin storage, cookies, and registered Capacitor plugin capabilities. Applications remain affected when CapacitorHttp is disabled because affected releases serve the proxy path regardless of that setting. This issue is fixed in versions 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1.","cveId":"CVE-2026-103922","cvssScore":9.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","severity":"critical","vendor":"npm","product":"@capacitor/android","affectedVersions":["pkg:npm/%40capacitor/android >= 6.0.0, < 6.2.2","pkg:npm/%40capacitor/android >= 7.0.0, < 7.6.9","pkg:npm/%40capacitor/ios >= 6.0.0, < 6.2.2","pkg:npm/%40capacitor/ios >= 7.0.0, < 7.6.9","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 6.0.0, < 6.2.2","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 7.0.0, < 7.6.9","pkg:maven/com.capacitorjs/core >= 6.0.0, < 6.2.2","pkg:maven/com.capacitorjs/core >= 7.0.0, < 7.6.9","pkg:npm/%40capacitor/android >= 8.5.0, < 8.5.1","pkg:npm/%40capacitor/ios >= 8.5.0, < 8.5.1","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 8.5.0, < 8.5.1","pkg:maven/com.capacitorjs/core >= 8.5.0, < 8.5.1","pkg:maven/com.capacitorjs/core >= 8.3.5, < 8.4.3","pkg:npm/%40capacitor/android >= 8.3.5, < 8.4.3","pkg:npm/%40capacitor/ios >= 8.3.5, < 8.4.3","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 8.3.5, < 8.4.3","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 8.0.0, <= 8.3.4","pkg:maven/com.capacitorjs/core >= 8.0.0, <= 8.3.4","pkg:npm/%40capacitor/android >= 8.0.0, <= 8.3.4","pkg:npm/%40capacitor/ios >= 8.0.0, <= 8.3.4"],"cwes":["CWE-346","CWE-441"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-rvm3-566m-v7fv","ecosystem:npm","ecosystem:swifturl","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ionic-team/capacitor/commit/430356a91e1419fc66862dc09835081aa501677e","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/80b6c5e81d062e1e158914040f49e044d95b7ccb","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/85ccc44151fdd5ae5e0d806d875766ef4b84ad5d","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/af9a287fef45f0ac68ce640cb42fed2d06b0f1b4","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/d5e3170ba0ff155fc542b7e6d16cff5201406540","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/ee586ae680887ba99d066616f976db149542d922","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/releases/tag/8.5.1","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/security/advisories/GHSA-rvm3-566m-v7fv","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-rvm3-566m-v7fv","type":"advisory","title":"OSV GHSA-rvm3-566m-v7fv"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103922","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/ionic-team/capacitor/commit/745b5f805bf77bc6463977cc7d718cd9de44ccbc","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor","type":"vendor","title":"OSV package"}],"epssScore":0.00213,"epssPercentile":0.10633,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T18:17:12.840Z","addedAt":"2026-10-01T19:50:41.041Z","updatedAt":"2026-10-06T01:54:27.398Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103922","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103922","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RVM3-566M-V7FV"}]}],"pagination":{"page":1,"limit":20,"total":912,"totalPages":46,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:19:19.337Z","durationMs":32,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":["ecosystem:maven"],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}