OmniFish Build of Payara security fixes summary

OmniFish proactively monitors, patches, and releases security fixes for vulnerabilities in the OmniFish Build of Payara across all supported versions, so your systems stay ahead of threats and compliant with enterprise standards. 

Get full access to OmniFish Build of Payara with all the security fixes applied on top of Payara Community — find out more about OmniFish Builds of Payara today and contact us for a free trial.

Vulnerability Severity Versions affected Fixed in version Summary
CVE-2021-23463 9.1 CRITICAL < 5.2026.4 5.2026.4 Improper Restriction of XML External Entity Reference in com.h2database:h2.
CVE-2022-48285 7.3 HIGH < 5.2026.4 5.2026.4 6.9: Remove javadoc from OpenMQ with CVE in jszip
CVE-2026-2586 9.1 CRITICAL < 5.2026.4 5.2026.4 9.1 and CVE-2026-2587 - 9.6: Patch JSF templating 2.1.4 with a CVE fix from 4.0.5 and 4.2.0
CVE-2026-2587 9.6 CRITICAL < 5.2026.4 5.2026.4 9.1 and CVE-2026-2587 - 9.6: Patch JSF templating 2.1.4 with a CVE fix from 4.0.5 and 4.2.0
CVE-2026-54512 8.1 HIGH < 5.2026.4 5.2026.4 8.1, CVE-2026-54513 - 8.1, CVE-2026-54514 - 5.3: Upgrade Jackson from 2.17.0 to 2.18.8 to fix CVEs in jackson-databind
CVE-2026-54513 8.1 HIGH < 5.2026.4 5.2026.4 8.1, CVE-2026-54513 - 8.1, CVE-2026-54514 - 5.3: Upgrade Jackson from 2.17.0 to 2.18.8 to fix CVEs in jackson-databind
CVE-2026-54514 5.3 MEDIUM < 5.2026.4 5.2026.4 8.1, CVE-2026-54513 - 8.1, CVE-2026-54514 - 5.3: Upgrade Jackson from 2.17.0 to 2.18.8 to fix CVEs in jackson-databind
CVE-2015-9251 6.1 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2016-10735 6.1 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2016-4055 6.5 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2017-18214 7.5 HIGH < 5.2026.3 5.2026.3 and several other CVEs in JavaScript libraries present in Weld Probe. Weld Probe is not enabled by default and it's meant to be used only in development. The Weld Probe functionality will be removed in the future
CVE-2018-14040 6.1 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2018-14041 6.1 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2018-14042 6.1 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2018-20676 6.1 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2018-20677 6.1 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2019-11358 6.1 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2019-8331 6.1 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2020-11022 6.1 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2020-11023 6.1 MEDIUM < 5.2026.3 5.2026.3 CVE-2016-4055, CVE-2015-9251, CVE-2016-10735, CVE-2018-14040, CVE-2018-14041, CVE-2018-14042, CVE-2018-20676, CVE-2018-20677, CVE-2019-11358, CVE-2019-8331, CVE-2020-11022, CVE-2020-11023, - Disabled Weld Probe, which exposed several CVEs in old versions of JavaScript components JQuery, Moment.js, and Bootstrap,
CVE-2022-24785 7.5 HIGH < 5.2026.3 5.2026.3 and several other CVEs in JavaScript libraries present in Weld Probe. Weld Probe is not enabled by default and it's meant to be used only in development. The Weld Probe functionality will be removed in the future
CVE-2022-34169 7.5 HIGH < 5.2026.3 5.2026.3 Upgrade Xalan from 2.7.2 to 2.7.3
CVE-2024-9342 6.3 MEDIUM < 5.2026.3 5.2026.3 Brute force prevention - port from GlassFish
CVE-2025-7962 6.0 MEDIUM < 5.2026.3 5.2026.3 Backported fix to Jakarta Mail from 1.6.8
CVE-2026-24457 9.1 CRITICAL < 5.2026.3 5.2026.3 Upgrade OpenMQ to 5.1.4.payara-p7
CVE-2020-27511 7.5 HIGH < 5.2026.2 5.2026.2 CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs
CVE-2020-36843 4.3 MEDIUM < 5.2026.2 5.2026.2 CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs
CVE-2023-28462 9.8 CRITICAL < 5.2026.2 5.2026.2 JNDI Exploit using context.rebind method when running Payara Server on JDK 8 lower than 1.8u181
CVE-2023-52428 7.5 HIGH < 5.2026.2 5.2026.2 CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs
CVE-2023-5763 6.8 MEDIUM < 5.2026.2 5.2026.2 In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.
CVE-2024-45687 2.4 LOW < 5.2026.2 5.2026.2 HTTP Server incorrectly accepting disallowed characters within header values
CVE-2024-47554 4.3 MEDIUM < 5.2026.2 5.2026.2 Upgrade Commons FileUpload and IO to fix CVEs
CVE-2024-57699 7.5 HIGH < 5.2026.2 5.2026.2 CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs
CVE-2024-7312 7.0 HIGH < 5.2026.2 5.2026.2 setting local Name and Port for /managment/domain URI
CVE-2024-9329 6.9 MEDIUM < 5.2026.2 5.2026.2 setting local Name and Port for /managment/domain URI
CVE-2025-14340 7.3 HIGH < 5.2026.2 5.2026.2 Admin Account Takeover via malicious URL payload
CVE-2025-1534 6.8 MEDIUM < 5.2026.2 5.2026.2 Cross-site Scripting in Admin Console
CVE-2025-48976 7.5 HIGH < 5.2026.2 5.2026.2 Upgrade Commons FileUpload and IO to fix CVEs
CVE-2025-53864 5.8 MEDIUM < 5.2026.2 5.2026.2 CVE-2025-53864, CVE-2023-52428, CVE-2024-57699 - upgrade components with CVEs
CVE-2014-8152 5.0 MEDIUM < 5.2026.1 5.2026.1 CVE-2023-44483 - Upgrade Santuario XMLSEC in Metro to 2.3.4
CVE-2017-12617 8.1 HIGH < 5.2026.1 5.2026.1 port from Tomcat
CVE-2021-27568 5.9 MEDIUM < 5.2026.1 5.2026.1 CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998
CVE-2021-31684 7.5 HIGH < 5.2026.1 5.2026.1 CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998
CVE-2021-40690 7.5 HIGH < 5.2026.1 5.2026.1 CVE-2023-44483 - Upgrade Santuario XMLSEC in Metro to 2.3.4
CVE-2022-1471 8.3 HIGH < 5.2026.1 5.2026.1 CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0
CVE-2022-36437 9.1 CRITICAL < 5.2026.1 5.2026.1 CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0
CVE-2022-42003 7.5 HIGH < 5.2026.1 5.2026.1 CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0
CVE-2022-42920 9.8 CRITICAL < 5.2026.1 5.2026.1 CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0
CVE-2023-1370 7.5 HIGH < 5.2026.1 5.2026.1 CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998
CVE-2023-24998 7.5 HIGH < 5.2026.1 5.2026.1 CVE-2021-31684, CVE-2023-24998, [sonatype-2014-0173]( - Upgrade components to fix CVE-2023-1370, CVE-2023-24998
CVE-2023-33264 4.3 MEDIUM < 5.2026.1 5.2026.1 CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0
CVE-2023-33265 8.8 HIGH < 5.2026.1 5.2026.1 CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0
CVE-2023-35116 4.7 MEDIUM < 5.2026.1 5.2026.1 CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0
CVE-2023-4043 5.9 MEDIUM < 5.2026.1 5.2026.1 Upgrade jsonp to 1.1.6.payara-p1 to fix CVE-2023-4043
CVE-2023-41699 6.1 MEDIUM < 5.2026.1 5.2026.1 Avoid protocol relative redirects
CVE-2023-44483 6.5 MEDIUM < 5.2026.1 5.2026.1 CVE-2023-44483 - Upgrade Santuario XMLSEC in Metro to 2.3.4
CVE-2023-45859 7.6 HIGH < 5.2026.1 5.2026.1 CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0
CVE-2023-45860 6.5 MEDIUM < 5.2026.1 5.2026.1 CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0
CVE-2024-8646 6.1 MEDIUM < 5.2026.1 5.2026.1 Avoid protocol relative redirects
CVE-2025-52999 8.7 HIGH < 5.2026.1 5.2026.1 CVE-2023-45859, CVE-2023-33264, CVE-2023-33265, CVE-2022-36437, CVE-2022-1471, CVE-2022-42003, CVE-2025-52999, CVE-2023-35116 - upgrade bcel to 6.7.0, Hazelcast to 5.3.6, SnakeYaml to 2.2, Jackson to 2.17.0

Generated at: 2026-07-13 23:31:05

Scroll to Top