GlassFish Security Fixes Summary

Vulnerability Severity Versions affected Fixed in version Summary
CVE-2026-12605 9.6 CRITICAL < 8.0.4 8.0.4 CSRF + SSRF leaks the admin tocken if the victim is authenticated into the Admin Console
CVE-2026-54515 5.3 MEDIUM 7.0.16 - 8.0.3 8.0.4 jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
CVE-2026-59889 6.5 MEDIUM 7.0.20 - 7.0.26, 7.1.1 - 8.0.3 8.0.4 jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
CVE-2024-9342 6.3 MEDIUM 7.0.16 - 7.0.25 8.0.3, 7.0.26 Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attempts
CVE-2026-12606 6.3 MEDIUM < 8.0.3 8.0.3 cannot properly parse the trailer section, which can be leveraged to perform HTTP request smuggling
CVE-2026-54512 8.1 HIGH 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
CVE-2026-54513 8.1 HIGH 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
CVE-2026-54514 5.3 MEDIUM 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
CVE-2026-54516 5.3 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields
CVE-2026-54517 5.3 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind has @JsonView bypass for setterless creator properties
CVE-2026-54518 6.5 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind has a @JsonView bypass for unwrapped creator parameters
CVE-2026-59888 6.5 MEDIUM 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
CVE-2026-24457 9.1 CRITICAL < 7.0.26 8.0.2, 7.1.1, 7.0.26 9.8 CRITICAL - An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server
CVE-2026-2586 9.1 CRITICAL 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.1 8.0.2, 7.1.1, 7.0.26 GlassFish's Administration Console is Vulnerable to RCE
CVE-2026-2587 9.6 CRITICAL 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.1 8.0.2, 7.1.1, 7.0.26 GlassFish's gadget handler is vulnerable to RCE
CVE-2026-18401 6.9 MEDIUM 7.0.16 - 7.0.25, 7.1.0, 8.0.0 8.0.1, 7.1.1, 7.0.26 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
CVE-2020-27511 7.5 HIGH < 7.0.26 8.0.0, 7.1.1, 7.0.26 HIGH, 7.5 - Upgrade Woodstock to 6.0.3 with a security fix for prototype
CVE-2020-5258 7.7 HIGH < 7.0.26 8.0.0, 7.1.0, 7.0.26 HIGH, 7.7 - Upgrade dojo.js to 1.16.5
CVE-2024-10029 4.5 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console
CVE-2024-10031 5.8 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through configuration file modifications
CVE-2024-10032 6.1 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2024-9343 6.1 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2025-12383 9.4 CRITICAL 7.0.20 - 7.0.21 7.0.22 Eclipse Jersey has a Race Condition
CVE-2024-9329 6.9 MEDIUM 7.0.16 7.0.17 Eclipse Glassfish improperly handles http parameters
CVE-2023-41080 6.1 MEDIUM < 7.0.10 7.0.10 (original CVE-2023-41080 in Tomcat) - Avoid protocol relative redirects
CVE-2024-8646 6.1 MEDIUM < 7.0.10 7.0.10 (original CVE-2023-41080 in Tomcat) - Avoid protocol relative redirects
CVE-2022-2712 6.5 MEDIUM < 7.0.0 7.0.0 relative path traversals possible with request path starting with './'
CVE-2022-46337 9.8 CRITICAL Not impacted GlassFish not affected because bundled Derby DB does not authenticate database users via LDAP

Generated at: 2026-08-06 14:27:11

Scroll to Top