github-actions[bot] commented on PR #16187: URL: https://github.com/apache/grails-core/pull/16187#issuecomment-5371466355
<!-- grails-vulnerability-scan --> ## 🔍 OSS Index Vulnerability Scan — pull request ❌ Vulnerabilities detected. ``` pkg:maven/ch.qos.logback/[email protected] - 1 vulnerability found! Vulnerability Title: [CVE-2026-19880] CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') ID: CVE-2026-19880 Description: Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More sp... CVSS Score: (6.3/10, Medium) CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVE: CVE-2026-19880 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-19880?component-type=maven&component-name=ch.qos.logback%2Flogback-classic&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 pkg:maven/org.mongodb/[email protected] - 1 vulnerability found! Vulnerability Title: [CVE-2026-18710] CWE-532: Information Exposure Through Log Files ID: CVE-2026-18710 Description: A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity... CVSS Score: (8.2/10, Critical) CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVE: CVE-2026-18710 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-18710?component-type=maven&component-name=org.mongodb%2Fmongodb-driver-sync&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 pkg:maven/tools.jackson.core/[email protected] - 2 vulnerabilities found! Vulnerability Title: [CVE-2026-68497] CWE-770: Allocation of Resources Without Limits or Throttling ID: CVE-2026-68497 Description: jackson-databind - Allocation of Resources Without Limits or Throttling CVSS Score: (8.7/10, Critical) CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE: CVE-2026-68497 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-68497?component-type=maven&component-name=tools.jackson.core%2Fjackson-databind&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 Vulnerability Title: [CVE-2026-19032] CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') ID: CVE-2026-19032 Description: com.fasterxml.jackson.core/jackson-databind - Unrestricted URI schemes in Path deserialization CVSS Score: (6.9/10, Medium) CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N CVE: CVE-2026-19032 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-19032?component-type=maven&component-name=tools.jackson.core%2Fjackson-databind&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 pkg:maven/org.springframework.security/[email protected] - 1 vulnerability found! Vulnerability Title: [CVE-2026-47838] CWE-287: Improper Authentication ID: CVE-2026-47838 Description: SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wr... CVSS Score: (8.1/10, Critical) CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVE: CVE-2026-47838 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-47838?component-type=maven&component-name=org.springframework.security%2Fspring-security-web&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 ``` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
