github-actions[bot] commented on PR #16031: URL: https://github.com/apache/grails-core/pull/16031#issuecomment-5803397704
<!-- grails-vulnerability-scan --> ## 🔍 OSS Index Vulnerability Scan — pull request ❌ Vulnerabilities detected. ``` pkg:maven/org.hibernate.orm/[email protected] - 1 vulnerability found! Vulnerability Title: [CVE-2026-77874] CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') ID: CVE-2026-77874 Description: Hibernate ORM - SQL injection via malicious JSON path argument CVSS Score: (7.1/10, High) CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVE: CVE-2026-77874 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-77874?component-type=maven&component-name=org.hibernate.orm%2Fhibernate-core&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 pkg:maven/tools.jackson.core/[email protected] - 2 vulnerabilities found! Vulnerability Title: [CVE-2026-91776] CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion') ID: CVE-2026-91776 Description: TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied ... CVSS Score: (6.9/10, Medium) CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVE: CVE-2026-91776 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-91776?component-type=maven&component-name=tools.jackson.core%2Fjackson-databind&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 Vulnerability Title: [CVE-2026-91777] CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion') ID: CVE-2026-91777 Description: Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-referen... CVSS Score: (6.9/10, Medium) CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVE: CVE-2026-91777 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-91777?component-type=maven&component-name=tools.jackson.core%2Fjackson-databind&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 pkg:maven/tools.jackson.core/[email protected] - 2 vulnerabilities found! Vulnerability Title: [CVE-2026-89407] CWE-1333 CWE-400 ID: CVE-2026-89407 Description: NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FL... CVSS Score: (7.5/10, High) CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE: CVE-2026-89407 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-89407?component-type=maven&component-name=tools.jackson.core%2Fjackson-core&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 Vulnerability Title: [CVE-2026-89425] CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion') ID: CVE-2026-89425 Description: com.fasterxml.jackson.core:jackson-core - Uncontrolled Resource Consumption CVSS Score: (7.5/10, High) CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE: CVE-2026-89425 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-89425?component-type=maven&component-name=tools.jackson.core%2Fjackson-core&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 pkg:maven/org.apache.tomcat.embed/[email protected] - 1 vulnerability found! Vulnerability Title: [CVE-2026-65927] CWE-193: Off-by-one Error ID: CVE-2026-65927 Description: Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the ... CVSS Score: (6.3/10, Medium) CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVE: CVE-2026-65927 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-65927?component-type=maven&component-name=org.apache.tomcat.embed%2Ftomcat-embed-core&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 pkg:maven/org.springframework.security/[email protected] - 1 vulnerability found! Vulnerability Title: [CVE-2026-47842] CWE-326: Inadequate Encryption Strength ID: CVE-2026-47842 Description: Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode... CVSS Score: (7.1/10, High) CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE: CVE-2026-47842 Reference: https://guide.sonatype.com/vulnerability/CVE-2026-47842?component-type=maven&component-name=org.springframework.security%2Fspring-security-crypto&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.2 ``` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
