Eclipse GlassFish security fixes summary
OmniFish proactively monitors, patches, and releases security fixes for GlassFish vulnerabilities across all supported versions, so your systems stay ahead of threats and compliant with enterprise standards.
Get full access to our GlassFish security fixes — explore support plans today or contact us for more information.
| Vulnerability | Severity | Versions affected | Fixed in version | Summary |
|---|---|---|---|---|
| CVE-2024-9342 | 6.3 MEDIUM | 7.0.16 - 7.0.25 | 8.0.3, 7.0.26 | Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attempts |
| CVE-2026-54512 | 8.1 HIGH | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 | 8.0.3, 7.1.1, 7.0.26 | jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation |
| CVE-2026-54513 | 8.1 HIGH | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 | 8.0.3, 7.1.1, 7.0.26 | jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) |
| CVE-2026-54514 | 5.3 MEDIUM | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 | 8.0.3, 7.1.1, 7.0.26 | jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF) |
| CVE-2026-54516 | 5.3 MEDIUM | 8.0.0 - 8.0.2 | 8.0.3 | jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields |
| CVE-2026-54517 | 5.3 MEDIUM | 8.0.0 - 8.0.2 | 8.0.3 | jackson-databind has @JsonView bypass for setterless creator properties |
| CVE-2026-54518 | 6.5 MEDIUM | 8.0.0 - 8.0.2 | 8.0.3 | jackson-databind has a @JsonView bypass for unwrapped creator parameters |
| CVE-2026-24457 | 9.8 CRITICAL | < 8.0.2 | 8.0.2 | 9.8 CRITICAL - An unsafe parsing of OpenMQ's configuration, allows to read arbitrary files from a MQ Broker's server |
| CVE-2026-2586 | 9.1 CRITICAL | 7.0.16 - 8.0.1 | 8.0.2, 7.1.1, 7.0.26 | GlassFish's Administration Console is Vulnerable to RCE |
| CVE-2026-2587 | 9.6 CRITICAL | 7.0.16 - 8.0.1 | 8.0.2, 7.1.1, 7.0.26 | GlassFish's gadget handler is vulnerable to RCE |
| CVE-2020-27511 | 7.5 HIGH | < 8.0.0 | 8.0.0, 7.1.1, 7.0.26 | HIGH, 7.5 - Upgrade Woodstock to 6.0.3 with a security fix for prototype |
| CVE-2020-5258 | 7.7 HIGH | < 8.0.0 | 8.0.0, 7.1.0, 7.0.26 | HIGH, 7.7 - Upgrade dojo.js to 1.16.5 |
| CVE-2024-10029 | 4.5 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console |
| CVE-2024-10031 | 5.8 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Stored XSS attacks through configuration file modifications |
| CVE-2024-10032 | 6.1 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console |
| CVE-2024-9343 | 6.1 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console |
| CVE-2025-12383 | 9.4 CRITICAL | 7.0.20 - 7.0.21 | 7.0.22 | Eclipse Jersey has a Race Condition |
| CVE-2024-9329 | 6.9 MEDIUM | 7.0.16 | 7.0.17 | Eclipse Glassfish improperly handles http parameters |
| CVE-2023-41080 | 6.1 MEDIUM | < 7.0.10 | 7.0.10 | Avoid protocol relative redirects in |
| CVE-2022-46337 | 9.8 CRITICAL | Not impacted | GlassFish not affected because bundled Derby DB does not authenticate database users via LDAP |
Generated at: 2026-07-12 18:23:22