org.yamcs:yamcs-core
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.yamcs:yamcs-corepage 1 of 1
- CVE-2026-42568MEDIUMCVSS 4.3EG 4.3✓ Fixed in 5.12.72026-05-26
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the…
- CVE-2026-44595MEDIUMCVSS 4.3EG 4.3✓ Fixed in 5.12.72026-05-27
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/…
- CVE-2026-44596CRITICALCVSS 9.8EG 6.5✓ Fixed in 5.12.72026-05-27
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or fail…
- CVE-2026-44632CRITICALCVSS 9.1EG 9.1✓ Fixed in 5.12.72026-05-27
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evalu…
- CVE-2026-46562CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.12.72026-05-27
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed w…
- CVE-2026-46621CRITICALCVSS 9.1EG 9.1✓ Fixed in 5.12.72026-05-27
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enf…
Check whether org.yamcs:yamcs-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.yamcs:yamcs-core CVEs against the assets you own.
Start Free Scan →