GlassFish Security Fixes Summary
| Vulnerability | Severity | Versions affected | Fixed in version | Summary |
|---|---|---|---|---|
| CVE-2024-9342 | 6.3 MEDIUM | 7.0.16 - 7.0.25 | 8.0.3, 7.0.26 | Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attempts |
| CVE-2026-54512 | 8.1 HIGH | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 | 8.0.3, 7.1.1, 7.0.26 | jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation |
| CVE-2026-54513 | 8.1 HIGH | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 | 8.0.3, 7.1.1, 7.0.26 | jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) |
| CVE-2026-54514 | 5.3 MEDIUM | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 | 8.0.3, 7.1.1, 7.0.26 | jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF) |
| CVE-2026-54516 | 5.3 MEDIUM | 8.0.0 - 8.0.2 | 8.0.3 | jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields |
| CVE-2026-54517 | 5.3 MEDIUM | 8.0.0 - 8.0.2 | 8.0.3 | jackson-databind has @JsonView bypass for setterless creator properties |
| CVE-2026-54518 | 6.5 MEDIUM | 8.0.0 - 8.0.2 | 8.0.3 | jackson-databind has a @JsonView bypass for unwrapped creator parameters |
| CVE-2026-24457 | 9.8 CRITICAL | < 8.0.2 | 8.0.2 | 9.8 CRITICAL - An unsafe parsing of OpenMQ's configuration, allows to read arbitrary files from a MQ Broker's server |
| CVE-2026-2586 | 9.1 CRITICAL | 7.0.16 - 8.0.1 | 8.0.2, 7.1.1, 7.0.26 | GlassFish's Administration Console is Vulnerable to RCE |
| CVE-2026-2587 | 9.6 CRITICAL | 7.0.16 - 8.0.1 | 8.0.2, 7.1.1, 7.0.26 | GlassFish's gadget handler is vulnerable to RCE |
| CVE-2020-27511 | 7.5 HIGH | < 8.0.0 | 8.0.0, 7.1.1, 7.0.26 | HIGH, 7.5 - Upgrade Woodstock to 6.0.3 with a security fix for prototype |
| CVE-2020-5258 | 7.7 HIGH | < 8.0.0 | 8.0.0, 7.1.0, 7.0.26 | HIGH, 7.7 - Upgrade dojo.js to 1.16.5 |
| CVE-2024-10029 | 4.5 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console |
| CVE-2024-10031 | 5.8 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Stored XSS attacks through configuration file modifications |
| CVE-2024-10032 | 6.1 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console |
| CVE-2024-9343 | 6.1 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console |
| CVE-2025-12383 | 9.4 CRITICAL | 7.0.20 - 7.0.21 | 7.0.22 | Eclipse Jersey has a Race Condition |
| CVE-2024-9329 | 6.9 MEDIUM | 7.0.16 | 7.0.17 | Eclipse Glassfish improperly handles http parameters |
| CVE-2023-41080 | 6.1 MEDIUM | < 7.0.10 | 7.0.10 | Avoid protocol relative redirects in |
| CVE-2022-46337 | 9.8 CRITICAL | Not impacted | GlassFish not affected because bundled Derby DB does not authenticate database users via LDAP |