...
| date | CVE | library | description | versions | Risk for Delft-FEWS | JIRA | upgrade strategy | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| July 2026 | bcprov-jdk18on-1.78.1.jar | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84. | 1.78.1 |
| |||||||||||||||
| June 2026 | spring-core-6.2.18.jar | Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18. | 6.2.18 |
| Upgrade to Stable 2025.01 or newer | ||||||||||||||
| June 2026 | spring-core-6.2.18.jar | Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | 6.2.18 |
| Upgrade to Stable 2025.01 or newer | ||||||||||||||
| June 2026 | spring-core-6.2.18.jar | A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | 6.2.18 |
| Upgrade to Stable 2025.01 or newer | ||||||||||||||
| June 2026 | spring-core-6.2.18.jar | Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | 6.2.18 |
| Upgrade to Stable 2025.01 or newer | ||||||||||||||
| June 2026 | spring-core-6.2.18.jar | Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | 6.2.18 |
| Upgrade to Stable 2025.01 or newer | ||||||||||||||
| June 2026 | spring-core-6.2.18.jar | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48. | 6.2.18 |
| Upgrade to Stable 2025.01 or newer | ||||||||||||||
| June 2026 | spring-core-6.2.18.jar | Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | 6.2.18 |
| Upgrade to Stable 2025.01 or newer | ||||||||||||||
| June 2026 | spring-core-6.2.18.jar | A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | 6.2.18 |
| Upgrade to Stable 2025.01 or newer | ||||||||||||||
| May 2026 | tomcat-*.jar | Missing Authorization vulnerability in Brecht Visual Link Preview visual-link-preview allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visual Link Preview: from n/a through <= 2.2.9. |
| ||||||||||||||||
| May 2026 | tomcat-*.jar | Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue. | 11.0.22 and lower 10.1.55 and lower 9.0.118and lower |
| |||||||||||||||
| May 2026 | netty-all-4.2.12.Final.jar | Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final. | 4.2.12.Final and lower 4.1.132.Final and lower |
| |||||||||||||||
| May 2026 | netty-all-4.2.12.Final.jar | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final. | 4.2.12.Final and lower 4.1.132.Final and lower |
| |||||||||||||||
| April 2026 | bootstrap.min.js | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0. | Before 4.0.0 | False positive. bootstraps Popover and tooltips are not used to display input data. Only static text is displayed. |
| No upgrade planned. | |||||||||||||
| April 2026 | bootstrap.min.js | A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered. | Before 4.0.0 | False positive. bootstraps Popover and tooltips are not used to display input data. Only static text is displayed. |
| No upgrade planned. | |||||||||||||
| April 2026 | itextpdf-5.5.13.4.jar | iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | 5.5.13.4 | False positive; the scanner is mixing the .NET iText version numbers with the Java ones. |
| Updated to 5.5.13.5 in Stable 2026.01 | |||||||||||||
| April 2026 | CVE-2021-37533 | xmlgraphics-commons-2.9.jar | Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711. | 2.9 |
| Updated to 2.11 in Stable 2024.01 - 2026.01 | |||||||||||||
| April 2026 | CVE-2020-29582 | kotlin-stdlib-1.9.10.jar | In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions. | 1.9.10 |
| Updated to 2.3.10 in Stable 2026.01 | |||||||||||||
| April 2026 | CVE-2026-24733 | tomcat-embed-core-11.0.14.jar | Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue. | 11.0.14 |
| Updated to 11.0.18 in Stable 2026.01 | |||||||||||||
| April 2026 | CVE-2025-67735 | netty-all-4.1.126.Final.jar | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue. | 1.11.0 |
| Updated to 1.18.2 in Stable 2026.01 | |||||||||||||
| February 2026 | CVE-2026-27171 | zlib1.dll | zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition. | 1.3.1 | Updated to 1.3.2 in Stable2026.01 | ||||||||||||||
| Februari 2026 | CVE-2014-3004 | castor-0.9.5p4.jar | The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document. | 0.9.5 | The castor library used by FEWS has been patched at the source code level in 2021 | False positive | |||||||||||||
| December 2025 | CVE-2023-35116 | jackson-databind | jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker. | 2.15.2 | FEWS-28837 | Updated to 2.15.4 in stable 2023.01 and newer branches, | |||||||||||||
| December 2025 | CVE-2025-30474 | commons-vfs2-2.9.0.jar | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue. | 2.9.0 | FEWS-32789 | ||||||||||||||
| December 2025 | CVE-2025-31672 | poi-ooxml-5.2.2.jar | Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in the zip. In this case, products reading the affected file could read different data because 1 of the zip entries with the duplicate name is selected over another but different products may choose a different zip entry. This issue affects Apache POI poi-ooxml before 5.4.0. poi-ooxml 5.4.0 has a check that throws an exception if zip entries with duplicate file names are found in the input file. Users are recommended to upgrade to version poi-ooxml 5.4.0, which fixes the issue. Please read https://poi.apache.org/security.html for recommendations about how to use the POI libraries securely. | 5.2.2 | upgrade apache_poi_ooxml to 5.4.1 (04/09/2025 09:43) | Upgrade to 2025.02 | |||||||||||||
| December 2025 | CVE-2023-33201 | bcprov-jdk15-1.69.jar | Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability. | 1.69 | FEWS-24727 | ||||||||||||||
| December 2025 | CVE-2025-48924 | commons-lang3-3.12.0.jar | Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue. | 3.12.0 | FEWS-31669 | ||||||||||||||
| December 2025 | CVE-2024-35255 | azure-identity-1.11.0.jar | Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | 1.11.0 | FEWS-27037 | ||||||||||||||
| February 2026 | CVE-2024-35255 | azure-identity-1.18.2.jar msal4j-1.24.0.jar | Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | 1.18.2 1.24.0 | FEWS-34475 | ||||||||||||||
| December 2025 | CVE-2024-26308 | commons-compress-1.21.jar | Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue. | 1.21 | FEWS-31669 | ||||||||||||||
| December 2025 | CVE-2023-33202 | bcprov-jdk15-1.69.jar | Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and PKCS7 objects. Parsing a file that has crafted ASN.1 data through the PEMParser causes an OutOfMemoryError, which can enable a denial of service attack. (For users of the FIPS Java API: BC-FJA 1.0.2.3 and earlier are affected; BC-FJA 1.0.2.4 is fixed.) | 1.69 | FEWS-24727 | ||||||||||||||
| December 2025 | CVE-2025-53864 | nimbus-jose-jwt-9.25.6 | Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson. | 9.25.6 | FEWS-31813 | ||||||||||||||
| December 2025 | CVE-2024-30171 | bcprov-jdk15-1.69.jar | An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. | 1.69 | FEWS-24727 |
...