Eclipse GlassFish security fixes summary

OmniFish proactively monitors, patches, and releases security fixes for GlassFish vulnerabilities across all supported versions, so your systems stay ahead of threats and compliant with enterprise standards. 

Get full access to our GlassFish security fixes — explore support plans today or contact us for more information.

Vulnerability Severity Versions affected Fixed in version Summary
CVE-2024-9342 6.3 MEDIUM 7.0.16 - 7.0.25 8.0.3, 7.0.26 Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attempts
CVE-2026-54512 8.1 HIGH 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
CVE-2026-54513 8.1 HIGH 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
CVE-2026-54514 5.3 MEDIUM 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 8.0.3, 7.1.1, 7.0.26 jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
CVE-2026-54516 5.3 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields
CVE-2026-54517 5.3 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind has @JsonView bypass for setterless creator properties
CVE-2026-54518 6.5 MEDIUM 8.0.0 - 8.0.2 8.0.3 jackson-databind has a @JsonView bypass for unwrapped creator parameters
CVE-2026-24457 9.8 CRITICAL < 8.0.2 8.0.2 9.8 CRITICAL - An unsafe parsing of OpenMQ's configuration, allows to read arbitrary files from a MQ Broker's server
CVE-2026-2586 9.1 CRITICAL 7.0.16 - 8.0.1 8.0.2, 7.1.1, 7.0.26 GlassFish's Administration Console is Vulnerable to RCE
CVE-2026-2587 9.6 CRITICAL 7.0.16 - 8.0.1 8.0.2, 7.1.1, 7.0.26 GlassFish's gadget handler is vulnerable to RCE
CVE-2020-27511 7.5 HIGH < 8.0.0 8.0.0, 7.1.1, 7.0.26 HIGH, 7.5 - Upgrade Woodstock to 6.0.3 with a security fix for prototype
CVE-2020-5258 7.7 HIGH < 8.0.0 8.0.0, 7.1.0, 7.0.26 HIGH, 7.7 - Upgrade dojo.js to 1.16.5
CVE-2024-10029 4.5 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console
CVE-2024-10031 5.8 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through configuration file modifications
CVE-2024-10032 6.1 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2024-9343 6.1 MEDIUM 7.0.16 - 7.0.25 7.0.26 Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2025-12383 9.4 CRITICAL 7.0.20 - 7.0.21 7.0.22 Eclipse Jersey has a Race Condition
CVE-2024-9329 6.9 MEDIUM 7.0.16 7.0.17 Eclipse Glassfish improperly handles http parameters
CVE-2023-41080 6.1 MEDIUM < 7.0.10 7.0.10 Avoid protocol relative redirects in
CVE-2022-46337 9.8 CRITICAL Not impacted GlassFish not affected because bundled Derby DB does not authenticate database users via LDAP

Generated at: 2026-07-12 18:23:22

Scroll to Top