IndexedVerified
JVM Security
Java, Kotlin, and Scala SAST rules aggregated across verified providers.
Fetch pack
greprules pack fetch jvm-security --engine opengrepcurl https://api.greprules.io/api/packs/jvm-security.tar.gz -o jvm-security.tar.gzIncluded rules
CVE-2026-55847: Allure Unsanitized Description Html
cve-2026-55847-allure-unsanitized-description-htmlCVE-2026-55405: Fail Open Escaping Fallbackcve-2026-55405-fail-open-escaping-fallbackCVE-2026-53698: Silverpeas Unvalidated Jsp Forward Path Traversalcve-2026-53698-silverpeas-unvalidated-jsp-forward-path-traversalCVE-2026-49328: Custom Improper Magic Byte Evaluationcve-2026-49328-custom-improper-magic-byte-evaluationCVE-2026-49270: Activemq Unsafe Factoryfindercve-2026-49270-activemq-unsafe-factoryfinderCVE-2026-49157: Insecure Dynamic Class Instantiationcve-2026-49157-insecure-dynamic-class-instantiationCVE-2026-48920: Emailext Extendedemailpublisherdescriptor Java Cwe 000 Cve 2026 48920cve-2026-48920-emailext-extendedemailpublisherdescriptor-java-cwe-000-cve-2026-48920CVE-2026-48480: Netty Ohttp Missing Final Chunk Checkcve-2026-48480-netty-ohttp-missing-final-chunk-checkCVE-2026-48040: Netty Jni Direct Buffer Offset Bypasscve-2026-48040-netty-jni-direct-buffer-offset-bypassCVE-2026-46605: Activemq Insecure Factoryfindercve-2026-46605-activemq-insecure-factoryfinderCVE-2026-46495: Jmx Authenticator Object Array Castcve-2026-46495-jmx-authenticator-object-array-castCVE-2026-45799: Kotlin Protobuf Missing Negative Length Checkcve-2026-45799-kotlin-protobuf-missing-negative-length-checkCVE-2026-45575: Insecure Hostnameverifier Chain Iterationcve-2026-45575-insecure-hostnameverifier-chain-iterationCVE-2026-45505: Activemq Unconstrained Factory Findercve-2026-45505-activemq-unconstrained-factory-finderCVE-2026-45205: Java Yaml Commons Configuration Uncontrolled Recursioncve-2026-45205-java-yaml-commons-configuration-uncontrolled-recursionCVE-2026-44900: Jws Payload Without Signature Verificationcve-2026-44900-jws-payload-without-signature-verificationCVE-2026-44714: Bytebuffer Deserializer Throws Ioexceptioncve-2026-44714-bytebuffer-deserializer-throws-ioexceptionCVE-2026-44596: Missing Rate Limiting Auth Endpointcve-2026-44596-missing-rate-limiting-auth-endpointCVE-2026-44248: Netty Replaying Decoder Readablebytes Doscve-2026-44248-netty-replaying-decoder-readablebytes-dosCVE-2026-43975: Java Torealpath Broad Catch Traversal Bypasscve-2026-43975-java-torealpath-broad-catch-traversal-bypassCVE-2026-42809: Polaris Iceberg Location Gate Missing Metadata Keycve-2026-42809-polaris-iceberg-location-gate-missing-metadata-keyCVE-2026-42198: Scram Client Unbounded Pbkdf2cve-2026-42198-scram-client-unbounded-pbkdf2CVE-2026-41901: Thymeleaf Cve 2026 41901 Typename Firstchar Shortcutcve-2026-41901-thymeleaf-cve-2026-41901-typename-firstchar-shortcutCVE-2026-41706: Spring Oauth2 Weak Uri Validationcve-2026-41706-spring-oauth2-weak-uri-validation24 of 346 loaded