security fixes summary - OmniFish Service Packs for Payara® Platform Community Edition
OmniFish proactively monitors, patches, and releases security fixes for vulnerabilities in Payara® Platform Community Edition across all supported versions, so your systems stay ahead of threats and compliant with enterprise standards.
Get full access to the OmniFish Service Packs with all the security fixes applied on top of Payara® Platform Community Edition — find out more about OmniFish Service Packs today and contact us for a free trial.
OmniFish is independent of Azul Systems, Inc., and Payara Foundation. Payara® is a trademark of the Payara Foundation.
| Vulnerability | Severity | Versions affected | Fixed in version | Summary |
|---|---|---|---|---|
| CVE-2021-23463 | 9.1 CRITICAL | < 5.2026.4 | 5.2026.4 | Improper Restriction of XML External Entity Reference in com.h2database:h2. |
| CVE-2022-48285 | 7.3 HIGH | < 5.2026.4 | 5.2026.4 | 6.9: Remove javadoc from OpenMQ with CVE in jszip |
| CVE-2026-2586 | 9.1 CRITICAL | < 5.2026.4 | 5.2026.4 | 9.1 and CVE-2026-2587 - 9.6: Patch JSF templating 2.1.4 with a CVE fix from 4.0.5 and 4.2.0 |
| CVE-2026-2587 | 9.6 CRITICAL | < 5.2026.4 | 5.2026.4 | 9.1 and CVE-2026-2587 - 9.6: Patch JSF templating 2.1.4 with a CVE fix from 4.0.5 and 4.2.0 |
| CVE-2026-54512 | 8.1 HIGH | < 5.2026.4 | 5.2026.4 | 8.1, CVE-2026-54513 - 8.1, CVE-2026-54514 - 5.3: Upgrade Jackson from 2.17.0 to 2.18.8 to fix CVEs in jackson-databind |
| CVE-2026-54513 | 8.1 HIGH | < 5.2026.4 | 5.2026.4 | 8.1, CVE-2026-54513 - 8.1, CVE-2026-54514 - 5.3: Upgrade Jackson from 2.17.0 to 2.18.8 to fix CVEs in jackson-databind |
| CVE-2026-54514 | 5.3 MEDIUM | < 5.2026.4 | 5.2026.4 | 8.1, CVE-2026-54513 - 8.1, CVE-2026-54514 - 5.3: Upgrade Jackson from 2.17.0 to 2.18.8 to fix CVEs in jackson-databind |
| CVE-2015-9251 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2016-10735 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2016-4055 | 6.5 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2017-18214 | 7.5 HIGH | < 5.2026.3 | 5.2026.3 | and several other CVEs in JavaScript libraries present in Weld Probe. Weld Probe is not enabled by default and it's meant to be used only in development. The Weld Probe functionality will be removed in the future |
| CVE-2018-14040 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2018-14041 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2018-14042 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2018-20676 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2018-20677 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2019-11358 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2019-8331 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2020-11022 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2020-11023 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2022-24785 | 7.5 HIGH | < 5.2026.3 | 5.2026.3 | and several other CVEs in JavaScript libraries present in Weld Probe. Weld Probe is not enabled by default and it's meant to be used only in development. The Weld Probe functionality will be removed in the future |
| CVE-2022-34169 | 7.5 HIGH | < 5.2026.3 | 5.2026.3 | Upgrade Xalan from 2.7.2 to 2.7.3 |
| CVE-2024-9342 | 6.3 MEDIUM | < 5.2026.3 | 5.2026.3 | Brute force prevention - port from GlassFish |
| CVE-2025-7962 | 6.0 MEDIUM | < 5.2026.3 | 5.2026.3 | Backported fix to Jakarta Mail from 1.6.8 |
| CVE-2026-24457 | 9.1 CRITICAL | < 5.2026.3 | 5.2026.3 | Upgrade OpenMQ to 5.1.4.payara-p7 |
| CVE-2020-27511 | 7.5 HIGH | < 5.2026.2 | 5.2026.2 | CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs |
| CVE-2020-36843 | 4.3 MEDIUM | < 5.2026.2 | 5.2026.2 | CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs |
| CVE-2023-28462 | 9.8 CRITICAL | < 5.2026.2 | 5.2026.2 | JNDI Exploit using context.rebind method when running Payara Server on JDK 8 lower than 1.8u181 |
| CVE-2023-52428 | 7.5 HIGH | < 5.2026.2 | 5.2026.2 | CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs |
| CVE-2023-5763 | 6.8 MEDIUM | < 5.2026.2 | 5.2026.2 | In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners. |
| CVE-2024-45687 | 2.4 LOW | < 5.2026.2 | 5.2026.2 | HTTP Server incorrectly accepting disallowed characters within header values |
| CVE-2024-47554 | 4.3 MEDIUM | < 5.2026.2 | 5.2026.2 | Upgrade Commons FileUpload and IO to fix CVEs |
| CVE-2024-57699 | 7.5 HIGH | < 5.2026.2 | 5.2026.2 | CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs |
| CVE-2024-7312 | 7.0 HIGH | < 5.2026.2 | 5.2026.2 | setting local Name and Port for /managment/domain URI |
| CVE-2024-9329 | 6.9 MEDIUM | < 5.2026.2 | 5.2026.2 | setting local Name and Port for /managment/domain URI |
| CVE-2025-14340 | 7.3 HIGH | < 5.2026.2 | 5.2026.2 | Admin Account Takeover via malicious URL payload |
| CVE-2025-1534 | 6.8 MEDIUM | < 5.2026.2 | 5.2026.2 | Cross-site Scripting in Admin Console |
| CVE-2025-48976 | 7.5 HIGH | < 5.2026.2 | 5.2026.2 | Upgrade Commons FileUpload and IO to fix CVEs |
| CVE-2025-53864 | 5.8 MEDIUM | < 5.2026.2 | 5.2026.2 | CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs |
| CVE-2014-8152 | 5.0 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2023-44483 - Upgrade Santuario XMLSEC in Metro to 2.3.4 |
| CVE-2017-12617 | 8.1 HIGH | < 5.2026.1 | 5.2026.1 | port from Tomcat |
| CVE-2021-27568 | 5.9 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998 |
| CVE-2021-31684 | 7.5 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998 |
| CVE-2021-40690 | 7.5 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-44483 - Upgrade Santuario XMLSEC in Metro to 2.3.4 |
| CVE-2022-1471 | 8.3 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2022-36437 | 9.1 CRITICAL | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2022-42003 | 7.5 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2022-42920 | 9.8 CRITICAL | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2023-1370 | 7.5 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998 |
| CVE-2023-24998 | 7.5 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998 |
| CVE-2023-33264 | 4.3 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2023-33265 | 8.8 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2023-35116 | 4.7 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2023-4043 | 5.9 MEDIUM | < 5.2026.1 | 5.2026.1 | Upgrade jsonp to 1.1.6.payara-p1 to fix CVE-2023-4043 |
| CVE-2023-41699 | 6.1 MEDIUM | < 5.2026.1 | 5.2026.1 | Avoid protocol relative redirects |
| CVE-2023-44483 | 6.5 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2023-44483 - Upgrade Santuario XMLSEC in Metro to 2.3.4 |
| CVE-2023-45859 | 7.6 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2023-45860 | 6.5 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2024-8646 | 6.1 MEDIUM | < 5.2026.1 | 5.2026.1 | Avoid protocol relative redirects |
| CVE-2025-52999 | 8.7 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
Generated at: 2026-07-13 23:31:05