net.sf.jasperreports:jasperreports
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting net.sf.jasperreports:jasperreportspage 1 of 1
- CVE-2025-10492CRITICALCVSS 9.8EG 9.8✓ Fixed in 7.0.42025-09-16
vulnerable: 3.6.0 ... 7.0.3 (85 versions)
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
- CVE-2026-6009HIGHCVSS 8.7EG 8.7✓ Fixed in 7.0.72026-05-19
vulnerable: 3.6.0 ... 7.0.6 (88 versions)
Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system
Check whether net.sf.jasperreports:jasperreports is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for net.sf.jasperreports:jasperreports CVEs against the assets you own.
Start Free Scan →