Eclipse GlassFish security fixes summary
OmniFish proactively monitors, patches, and releases security fixes for GlassFish vulnerabilities across all supported versions, so your systems stay ahead of threats and compliant with enterprise standards.
Get full access to our GlassFish security fixes — explore support plans today or contact us for more information.
| Vulnerability | Severity | Versions affected | Fixed in version | Summary |
|---|---|---|---|---|
| CVE-2026-12605 | 9.6 CRITICAL | < 8.0.4 | 8.0.4 | CSRF + SSRF leaks the admin tocken if the victim is authenticated into the Admin Console |
| CVE-2026-54515 | 5.3 MEDIUM | 7.0.16 - 8.0.3 | 8.0.4 | jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties |
| CVE-2026-59889 | 6.5 MEDIUM | 7.0.20 - 7.0.26, 7.1.1 - 8.0.3 | 8.0.4 | jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization |
| CVE-2024-9342 | 6.3 MEDIUM | 7.0.16 - 7.0.25 | 8.0.3, 7.0.26 | Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attempts |
| CVE-2026-12606 | 6.3 MEDIUM | < 8.0.3 | 8.0.3 | cannot properly parse the trailer section, which can be leveraged to perform HTTP request smuggling |
| CVE-2026-54512 | 8.1 HIGH | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 | 8.0.3, 7.1.1, 7.0.26 | jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation |
| CVE-2026-54513 | 8.1 HIGH | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 | 8.0.3, 7.1.1, 7.0.26 | jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) |
| CVE-2026-54514 | 5.3 MEDIUM | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 | 8.0.3, 7.1.1, 7.0.26 | jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF) |
| CVE-2026-54516 | 5.3 MEDIUM | 8.0.0 - 8.0.2 | 8.0.3 | jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields |
| CVE-2026-54517 | 5.3 MEDIUM | 8.0.0 - 8.0.2 | 8.0.3 | jackson-databind has @JsonView bypass for setterless creator properties |
| CVE-2026-54518 | 6.5 MEDIUM | 8.0.0 - 8.0.2 | 8.0.3 | jackson-databind has a @JsonView bypass for unwrapped creator parameters |
| CVE-2026-59888 | 6.5 MEDIUM | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.2 | 8.0.3, 7.1.1, 7.0.26 | jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy |
| CVE-2026-24457 | 9.1 CRITICAL | < 7.0.26 | 8.0.2, 7.1.1, 7.0.26 | 9.8 CRITICAL - An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server |
| CVE-2026-2586 | 9.1 CRITICAL | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.1 | 8.0.2, 7.1.1, 7.0.26 | GlassFish's Administration Console is Vulnerable to RCE |
| CVE-2026-2587 | 9.6 CRITICAL | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 - 8.0.1 | 8.0.2, 7.1.1, 7.0.26 | GlassFish's gadget handler is vulnerable to RCE |
| CVE-2026-18401 | 6.9 MEDIUM | 7.0.16 - 7.0.25, 7.1.0, 8.0.0 | 8.0.1, 7.1.1, 7.0.26 | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| CVE-2020-27511 | 7.5 HIGH | < 7.0.26 | 8.0.0, 7.1.1, 7.0.26 | HIGH, 7.5 - Upgrade Woodstock to 6.0.3 with a security fix for prototype |
| CVE-2020-5258 | 7.7 HIGH | < 7.0.26 | 8.0.0, 7.1.0, 7.0.26 | HIGH, 7.7 - Upgrade dojo.js to 1.16.5 |
| CVE-2024-10029 | 4.5 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console |
| CVE-2024-10031 | 5.8 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Stored XSS attacks through configuration file modifications |
| CVE-2024-10032 | 6.1 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console |
| CVE-2024-9343 | 6.1 MEDIUM | 7.0.16 - 7.0.25 | 7.0.26 | Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console |
| CVE-2025-12383 | 9.4 CRITICAL | 7.0.20 - 7.0.21 | 7.0.22 | Eclipse Jersey has a Race Condition |
| CVE-2024-9329 | 6.9 MEDIUM | 7.0.16 | 7.0.17 | Eclipse Glassfish improperly handles http parameters |
| CVE-2023-41080 | 6.1 MEDIUM | < 7.0.10 | 7.0.10 | (original CVE-2023-41080 in Tomcat) - Avoid protocol relative redirects |
| CVE-2024-8646 | 6.1 MEDIUM | < 7.0.10 | 7.0.10 | (original CVE-2023-41080 in Tomcat) - Avoid protocol relative redirects |
| CVE-2022-2712 | 6.5 MEDIUM | < 7.0.0 | 7.0.0 | relative path traversals possible with request path starting with './' |
| CVE-2022-46337 | 9.8 CRITICAL | Not impacted | GlassFish not affected because bundled Derby DB does not authenticate database users via LDAP |
Generated at: 2026-08-06 14:27:11