Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
High
Jackson
jackson-databind
Authorization Bypass
>=2.15.0 <2.18.8, >=2.19.0 <2.21.4
Jul 29, 2026
High
Quarkus
Quarkus
Authorization Bypass
<3.20.6.1, >=3.21.0 <3.27.3.1, >=3.30.0 <3.33.1.1, >=3.34.0 <3.35.1.1
Jul 29, 2026
Medium
Quarkus
Quarkus
Denial of Service
<3.20.5, >=3.21.0 <3.27.2, >=3.30.0 <3.31.0
Jul 29, 2026
Critical
Quarkus
Quarkus
Authorization Bypass
>=2.9.0.CR1 <3.8.6.1, >=3.9.0.CR1 <3.15.3.1, >=3.16.0.CR1 <3.18.0.CR1
Jul 29, 2026
High
Quarkus
Quarkus
Information Exposure
<3.2.12.Final, >=3.3.0.CR1 <=3.8.3, >=3.9.0.CR1 <=3.9.1
Jul 29, 2026
High
Next.js
Next.js
Server-Side Request Forgery
URL Redirect/Open Redirect
>=12.0.0 <15.5.21, >=16.0.0 <16.2.11
Jul 24, 2026
Critical
Ingress NGINX
NGINX (ngx_http_proxy_v2_module and ngx_http_grpc_module); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Heap-based Buffer Overflow
NGINX Open Source 1.13.10 through 1.31.1; NGINX Plus R33 through R37.0.1; Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
Critical
Ingress NGINX
NGINX (script engine, map directive); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Heap-based Buffer Overflow
NGINX Open Source 0.9.6 through 1.31.2 (map regex support introduced in 0.9.6, 2011); Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
Medium
Ingress NGINX
NGINX (ngx_http_charset_module); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Buffer Over-read
Information Disclosure
NGINX Open Source 0.3.50 through 1.31.1; Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
High
Jetty
Eclipse Jetty
Authorization Bypass
>=9.4.0 <9.4.63, >=10.0.0 <10.0.31, >=11.0.0 <11.0.31, >=12.0.0 <12.0.36, >=12.1.0 <12.1.10
Jul 16, 2026
Medium
Jetty
Eclipse Jetty
HTTP Request Smuggling
>=9.4.0 <9.4.61, >=10.0.0 <10.0.29, >=11.0.0 <11.0.29, >=12.0.0 <12.0.35, >=12.1.0 <12.1.9
Jul 16, 2026
Low
Apache Tomcat
Apache Tomcat
Authorization Bypass
>=8.5.0 <=8.5.100, >=9.0.0.M1 <9.0.120, >=10.1.0-M1 <10.1.57, >=11.0.0-M1 <11.0.24
Jul 16, 2026
Medium
Node.js
Http Proxy Middleware
Improper Input Validation (4.16)
>=0.16.0 <2.0.10 >=3.0.0 <3.0.6 >=4.0.0 <4.1.0
Jul 14, 2026
High
Protocol Buffers
Protocol Buffers
Denial of Service
<3.25.5, >=4.0.0-RC1 <4.27.5, >=4.28.0-RC1 <4.28.2
Jul 9, 2026
No results found
Please enter a valid Vulnerability ID number or Technology name.
