Eclipse GlassFish security fixes summary

OmniFish proactively monitors, patches, and releases security fixes for GlassFish vulnerabilities across all supported versions, so your systems stay ahead of threats and compliant with enterprise standards. 

Get full access to our GlassFish security fixes — explore support plans today or contact us for more information.

Vulnerability Severity Versions affected Fixed in version Summary
CVE-2026-12605 9.6 CRITICAL < 8.0.4 8.0.4 CSRF + SSRF leaks the admin tocken if the victim is authenticated into the Admin Console
CVE-2026-54515 5.3 MEDIUM 7.0.16 - 8.0.3 8.0.4 jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
CVE-2026-59889 6.5 MEDIUM 7.0.20 - 7.0.26, 7.1.1 - 8.0.3 8.0.4 jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization
CVE-2024-9342 6.3 MEDIUM 7.0.16 - 7.0.25 8.0.3, 7.0.26 Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attempts
CVE-2026-12606 6.3 MEDIUM < 8.0.3 8.0.3 cannot properly parse the trailer section, which can be leveraged to perform HTTP request smuggling
CVE-2026-54512 8.1 HIGH 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
CVE-2026-54513 8.1 HIGH 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
CVE-2026-54514 5.3 MEDIUM 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
CVE-2026-54516 5.3 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields
CVE-2026-54517 5.3 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind has @JsonView bypass for setterless creator properties
CVE-2026-54518 6.5 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind has a @JsonView bypass for unwrapped creator parameters
CVE-2026-59888 6.5 MEDIUM 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
CVE-2026-24457 9.1 CRITICAL < 7.0.26 8.0.2, 7.1.1, 7.0.26 9.8 CRITICAL - An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server
CVE-2026-2586 9.1 CRITICAL 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.1 8.0.2, 7.1.1, 7.0.26 GlassFish's Administration Console is Vulnerable to RCE
CVE-2026-2587 9.6 CRITICAL 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.1 8.0.2, 7.1.1, 7.0.26 GlassFish's gadget handler is vulnerable to RCE
CVE-2026-18401 6.9 MEDIUM 7.0.16 - 7.0.25, 7.1.0, 8.0.0 8.0.1, 7.1.1, 7.0.26 jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition
CVE-2020-27511 7.5 HIGH < 7.0.26 8.0.0, 7.1.1, 7.0.26 HIGH, 7.5 - Upgrade Woodstock to 6.0.3 with a security fix for prototype
CVE-2020-5258 7.7 HIGH < 7.0.26 8.0.0, 7.1.0, 7.0.26 HIGH, 7.7 - Upgrade dojo.js to 1.16.5
CVE-2024-10029 4.5 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console
CVE-2024-10031 5.8 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through configuration file modifications
CVE-2024-10032 6.1 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2024-9343 6.1 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2025-12383 9.4 CRITICAL 7.0.20 - 7.0.21 7.0.22 Eclipse Jersey has a Race Condition
CVE-2024-9329 6.9 MEDIUM 7.0.16 7.0.17 Eclipse Glassfish improperly handles http parameters
CVE-2023-41080 6.1 MEDIUM < 7.0.10 7.0.10 (original CVE-2023-41080 in Tomcat) - Avoid protocol relative redirects
CVE-2024-8646 6.1 MEDIUM < 7.0.10 7.0.10 (original CVE-2023-41080 in Tomcat) - Avoid protocol relative redirects
CVE-2022-2712 6.5 MEDIUM < 7.0.0 7.0.0 relative path traversals possible with request path starting with './'
CVE-2022-46337 9.8 CRITICAL Not impacted GlassFish not affected because bundled Derby DB does not authenticate database users via LDAP

Generated at: 2026-08-06 14:27:11

Scroll to Top