Index
Search
Search the public record. Drafts and scheduled notes are not included.
news
Camel Quarkus XXE is CVE-2026-88789
Apache disclosed CVE-2026-88789 in Camel Quarkus: the Xalan-backed XSLT support factory drops JAXP external-access hardening, enabling XXE that can read local files or reach internal hosts. CVSS 3.1 8.6 from Apache. Fixed in 3.33.3 and 3.40.0. A public reproducer exists. Not in CISA KEV.
Published 1h ago
news
Apache Struts 7.4.0 fixes four security flaws
On 5 October 2026 Apache published S2-075 through S2-078 for Struts, covering OGNL injection in the legacy RESTful mapper, BigDecimal response expansion, an unbounded REST body read, and a shared date/time message formatter. Fixes ship in 7.4.0 and 6.12.0. No CVSS scores or CISA KEV listings yet.
Published 3h ago
news
OpenOffice Java bug has no released fix
CVE-2026-59265 can run code when a person opens a crafted document in Apache OpenOffice 4.1.16 or earlier. There is no CVSS score, no KEV listing, and no finished 4.1.17 release.
Published 5h ago
CVE-2026-104711
OGNL injection in the legacy RESTful action mapper
RCE
Published 19h ago
CVE-2026-104712
Disproportionate BigDecimal response expansion (DoS)
DoS
Published 19h ago
CVE-2026-104713
Unbounded REST plugin request body read (DoS)
DoS
Published 19h ago
CVE-2026-104714
Shared message formatter leaks date or time across requests
Info disclosure
Published 19h ago
CVE-2026-59265
OpenOffice Java document code execution
RCE
Published 3d ago
CVE-2026-88789
Camel Quarkus Xalan TransformerFactory drops XXE hardening
Other
Published 4d ago
CVE-2021-44228
Apache Log4j JNDI remote code execution
RCE
Published 10 Dec 2021