OmniFish Build of Payara security fixes summary
OmniFish proactively monitors, patches, and releases security fixes for vulnerabilities in the OmniFish Build of Payara across all supported versions, so your systems stay ahead of threats and compliant with enterprise standards.
Get full access to OmniFish Build of Payara with all the security fixes applied on top of Payara Community — find out more about OmniFish Builds of Payara today and contact us for a free trial.
| Vulnerability | Severity | Versions affected | Fixed in version | Summary |
|---|---|---|---|---|
| CVE-2021-23463 | 9.1 CRITICAL | < 5.2026.4 | 5.2026.4 | Improper Restriction of XML External Entity Reference in com.h2database:h2. |
| CVE-2022-48285 | 7.3 HIGH | < 5.2026.4 | 5.2026.4 | 6.9: Remove javadoc from OpenMQ with CVE in jszip |
| CVE-2026-2586 | 9.1 CRITICAL | < 5.2026.4 | 5.2026.4 | 9.1 and CVE-2026-2587 - 9.6: Patch JSF templating 2.1.4 with a CVE fix from 4.0.5 and 4.2.0 |
| CVE-2026-2587 | 9.6 CRITICAL | < 5.2026.4 | 5.2026.4 | 9.1 and CVE-2026-2587 - 9.6: Patch JSF templating 2.1.4 with a CVE fix from 4.0.5 and 4.2.0 |
| CVE-2026-54512 | 8.1 HIGH | < 5.2026.4 | 5.2026.4 | 8.1, CVE-2026-54513 - 8.1, CVE-2026-54514 - 5.3: Upgrade Jackson from 2.17.0 to 2.18.8 to fix CVEs in jackson-databind |
| CVE-2026-54513 | 8.1 HIGH | < 5.2026.4 | 5.2026.4 | 8.1, CVE-2026-54513 - 8.1, CVE-2026-54514 - 5.3: Upgrade Jackson from 2.17.0 to 2.18.8 to fix CVEs in jackson-databind |
| CVE-2026-54514 | 5.3 MEDIUM | < 5.2026.4 | 5.2026.4 | 8.1, CVE-2026-54513 - 8.1, CVE-2026-54514 - 5.3: Upgrade Jackson from 2.17.0 to 2.18.8 to fix CVEs in jackson-databind |
| CVE-2015-9251 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2016-10735 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2016-4055 | 6.5 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2017-18214 | 7.5 HIGH | < 5.2026.3 | 5.2026.3 | and several other CVEs in JavaScript libraries present in Weld Probe. Weld Probe is not enabled by default and it's meant to be used only in development. The Weld Probe functionality will be removed in the future |
| CVE-2018-14040 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2018-14041 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2018-14042 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2018-20676 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2018-20677 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2019-11358 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2019-8331 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2020-11022 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2020-11023 | 6.1 MEDIUM | < 5.2026.3 | 5.2026.3 | CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap, |
| CVE-2022-24785 | 7.5 HIGH | < 5.2026.3 | 5.2026.3 | and several other CVEs in JavaScript libraries present in Weld Probe. Weld Probe is not enabled by default and it's meant to be used only in development. The Weld Probe functionality will be removed in the future |
| CVE-2022-34169 | 7.5 HIGH | < 5.2026.3 | 5.2026.3 | Upgrade Xalan from 2.7.2 to 2.7.3 |
| CVE-2024-9342 | 6.3 MEDIUM | < 5.2026.3 | 5.2026.3 | Brute force prevention - port from GlassFish |
| CVE-2025-7962 | 6.0 MEDIUM | < 5.2026.3 | 5.2026.3 | Backported fix to Jakarta Mail from 1.6.8 |
| CVE-2026-24457 | 9.1 CRITICAL | < 5.2026.3 | 5.2026.3 | Upgrade OpenMQ to 5.1.4.payara-p7 |
| CVE-2020-27511 | 7.5 HIGH | < 5.2026.2 | 5.2026.2 | CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs |
| CVE-2020-36843 | 4.3 MEDIUM | < 5.2026.2 | 5.2026.2 | CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs |
| CVE-2023-28462 | 9.8 CRITICAL | < 5.2026.2 | 5.2026.2 | JNDI Exploit using context.rebind method when running Payara Server on JDK 8 lower than 1.8u181 |
| CVE-2023-52428 | 7.5 HIGH | < 5.2026.2 | 5.2026.2 | CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs |
| CVE-2023-5763 | 6.8 MEDIUM | < 5.2026.2 | 5.2026.2 | In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners. |
| CVE-2024-45687 | 2.4 LOW | < 5.2026.2 | 5.2026.2 | HTTP Server incorrectly accepting disallowed characters within header values |
| CVE-2024-47554 | 4.3 MEDIUM | < 5.2026.2 | 5.2026.2 | Upgrade Commons FileUpload and IO to fix CVEs |
| CVE-2024-57699 | 7.5 HIGH | < 5.2026.2 | 5.2026.2 | CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs |
| CVE-2024-7312 | 7.0 HIGH | < 5.2026.2 | 5.2026.2 | setting local Name and Port for /managment/domain URI |
| CVE-2024-9329 | 6.9 MEDIUM | < 5.2026.2 | 5.2026.2 | setting local Name and Port for /managment/domain URI |
| CVE-2025-14340 | 7.3 HIGH | < 5.2026.2 | 5.2026.2 | Admin Account Takeover via malicious URL payload |
| CVE-2025-1534 | 6.8 MEDIUM | < 5.2026.2 | 5.2026.2 | Cross-site Scripting in Admin Console |
| CVE-2025-48976 | 7.5 HIGH | < 5.2026.2 | 5.2026.2 | Upgrade Commons FileUpload and IO to fix CVEs |
| CVE-2025-53864 | 5.8 MEDIUM | < 5.2026.2 | 5.2026.2 | CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs |
| CVE-2014-8152 | 5.0 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2023-44483 - Upgrade Santuario XMLSEC in Metro to 2.3.4 |
| CVE-2017-12617 | 8.1 HIGH | < 5.2026.1 | 5.2026.1 | port from Tomcat |
| CVE-2021-27568 | 5.9 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998 |
| CVE-2021-31684 | 7.5 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998 |
| CVE-2021-40690 | 7.5 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-44483 - Upgrade Santuario XMLSEC in Metro to 2.3.4 |
| CVE-2022-1471 | 8.3 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2022-36437 | 9.1 CRITICAL | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2022-42003 | 7.5 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2022-42920 | 9.8 CRITICAL | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2023-1370 | 7.5 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998 |
| CVE-2023-24998 | 7.5 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998 |
| CVE-2023-33264 | 4.3 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2023-33265 | 8.8 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2023-35116 | 4.7 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2023-4043 | 5.9 MEDIUM | < 5.2026.1 | 5.2026.1 | Upgrade jsonp to 1.1.6.payara-p1 to fix CVE-2023-4043 |
| CVE-2023-41699 | 6.1 MEDIUM | < 5.2026.1 | 5.2026.1 | Avoid protocol relative redirects |
| CVE-2023-44483 | 6.5 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2023-44483 - Upgrade Santuario XMLSEC in Metro to 2.3.4 |
| CVE-2023-45859 | 7.6 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2023-45860 | 6.5 MEDIUM | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
| CVE-2024-8646 | 6.1 MEDIUM | < 5.2026.1 | 5.2026.1 | Avoid protocol relative redirects |
| CVE-2025-52999 | 8.7 HIGH | < 5.2026.1 | 5.2026.1 | CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0 |
Generated at: 2026-07-13 23:31:05